# Timelion with live streaming

**URL:** <https://discuss.elastic.co/t/timelion-with-live-streaming/190323>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [July 13, 2019, 1:06am UTC](https://discuss.elastic.co/t/timelion-with-live-streaming/190323 "2019-07-13T01:06:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![areyja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/areyja/32/50060_2.png) [@areyja](https://discuss.elastic.co/u/areyja)\
**Post date:** [July 13, 2019, 1:06am UTC](https://discuss.elastic.co/t/timelion-with-live-streaming/190323/1 "2019-07-13T01:06:28Z")

</div>

Hello ELK Gurus,  
Pl excuse my ignorance if this is very common issue and mistakes I am doing. I am 1 week into ELK.

I have set ELK on a single RHEL server. I have jdbc input from logstash sending data to elastic. I took care of doc\_id so I do not have dups pumped. I am trying to use this live data in timelion. However due to nature of my logstash(jdbc input) schedule (\* \* \* \* \*), logstash is in collecting, dying, resurrecting, collecting loop.

As a result, if you see the right side of time graph, the count is very high. shown by encircled area. As time passes by, or when window moves, the data normalizes fine, however at the edge of the graph it is messed up. It always remains high like shown in pic

 ![myBlah](https://us1.discourse-cdn.com/elastic/original/3X/4/5/45b32095648addf4f71644901d75025c770644f0.jpeg)

May be it is messed up because of time(2-3 min) elastic is taking to resolve/normalize incoming stream? What should I do handle this?

Regards,  
/a

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [July 18, 2019, 11:36am UTC](https://discuss.elastic.co/t/timelion-with-live-streaming/190323/2 "2019-07-18T11:36:15Z")

</div>

Timelion is basically displaying what it's coming from elasticsearch. The best thing to do would be to offset the data slightly so that it only displays the normalized data.

---

<div class="post-metadata">

**Author:** ![areyja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/areyja/32/50060_2.png) [@areyja](https://discuss.elastic.co/u/areyja)\
**Post date:** [July 18, 2019, 6:43pm UTC](https://discuss.elastic.co/t/timelion-with-live-streaming/190323/3 "2019-07-18T18:43:12Z")

</div>

Thank You. Yes make sense. In my case offsetting it wasn't an option.  
I had to track column to not read what was read before. Relieving elastic ingesting and normalizing a large volume almost every minute.

/a

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2019, 6:43pm UTC](https://discuss.elastic.co/t/timelion-with-live-streaming/190323/4 "2019-08-15T18:43:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
